@avgeek-oss scope. The repository’s .npmrc maps that scope to GitHub Packages; other dependencies come from npm. No sibling checkout or unpublished library source is required. Published Mill images already contain these dependencies and need no npm credentials.
GitHub Packages requires authentication to install public npm packages. Use a GitHub classic personal access token with read:packages, following GitHub’s npm registry authentication guide.
Local development and source builds
Log in once with your GitHub username and the token as the password:.npmrc, outside the repository. The wrapper also accepts NODE_AUTH_TOKEN from a secret manager or NPM_CONFIG_USERCONFIG pointing to a user configuration file. It creates an owner-only temporary npm configuration for the child command and removes it when the command finishes. Keep credentials outside the checkout and never commit them.
For a Docker source build, use the same wrapper. With bundled PostgreSQL, set the API’s DATABASE_URL in .env to postgres://mill:<POSTGRES_PASSWORD>@postgres:5432/mill, using the actual password generated by init-env. The 127.0.0.1:55432 development URL is for Node running on the host, not for the API container:
api and web targets and sends NODE_AUTH_TOKEN as the npm_token BuildKit secret. The Dockerfile creates the npm configuration in a temporary filesystem only during dependency installation. It does not use a token build argument or runtime environment variable. The default Compose file is image-only and needs no npm token. See Docker’s build secret documentation.
For a direct Docker build, run:
Continuous integration
The verify jobs configureactions/setup-node for the scoped registry and pass the job’s GITHUB_TOKEN to the install step as NODE_AUTH_TOKEN. Source verification, review-artifact builds, and release-image builds pass it to BuildKit. Workflows request packages:read where needed, and reusable workflow callers preserve that permission.
The shared package’s Manage Actions access settings must grant avgeek-oss/mill read access. Adding the permission to a workflow does not grant access to a different repository’s package by itself. A package maintainer must configure that grant; see GitHub’s package access guidance.
An authentication or access failure should fail installation. Do not copy the library into Mill, disable the install gate, or commit a replacement token. CI does not publish the design system or require package write permission.